• DocumentCode
    1130210
  • Title

    TUA: A Novel Compromise-Resilient Authentication Architecture for Wireless Mesh Networks

  • Author

    Lin, Xiaodong ; Lu, Rongxing ; Ho, Pin-Han ; Shen, Xuemin Sherman ; Cao, Zhenfu

  • Author_Institution
    Univ. of Waterloo, Waterloo
  • Volume
    7
  • Issue
    4
  • fYear
    2008
  • fDate
    4/1/2008 12:00:00 AM
  • Firstpage
    1389
  • Lastpage
    1399
  • Abstract
    User authentication is essential in service-oriented communication networks to identify and reject any unauthorized network access. The state-of-the-art practice in securing wireless networks is based on the authentication, authorization and accounting (AAA) framework where one or multiple identical and duplicated AAA servers are adopted to authenticate mobile users (MUs), handle authorization requests, and collect accounting data. However, the conventional AAA framework cannot tolerate a server compromise event due to misuse, misconfiguration, and malicious access, etc., which may cause serious damages and resource abuses to the network operation. In this paper, we propose a novel design paradigm toward a compromise-resilient authentication architecture in service-oriented wireless mesh networks (WMNs) based on the (t, n) threshold signature technique, termed Threshold User Authentication (TUA) scheme. With the TUA scheme, only t or more out of n AAA servers in the WMN can cooperatively grant the network access to a MU, while any t-1 or less cannot. Detailed protocol-aspect design and implementations are presented. Extensive analysis on efficiency and reliability of authentication functionality is conducted to gain a deeper understanding on the parameter settings and optimization, which demonstrates the effectiveness of the TUA scheme. We conclude that the proposed authentication scheme can contribute to the WMN network design in metropolitan areas where numerous mesh points (MPs) coexist and are managed under a single control plane with multiple distributed AAA servers.
  • Keywords
    digital signatures; mobile radio; telecommunication security; AAA framework; accounting data; authentication functionality; authorization requests; compromise-resilient authentication architecture; mesh points; metropolitan areas; mobile users; parameter optimization; parameter settings; server compromise event; service-oriented communication networks; service-oriented wireless mesh networks; threshold signature technique; threshold user authentication; unauthorized network access; Authentication; Authorization; Communication networks; Communication system control; Communication system security; DSL; Network servers; Urban areas; Wireless communication; Wireless mesh networks;
  • fLanguage
    English
  • Journal_Title
    Wireless Communications, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1536-1276
  • Type

    jour

  • DOI
    10.1109/TWC.2008.060990
  • Filename
    4489766